CVE-2018-8552
CVE-2018-8552
Vexday Risk Score
35Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS —EPSS 51.0%KEV nãoPoC públicaNuclei —Metasploit —Patch —
Lifecycle
14 Nov 2018Published on NVD
30 Nov 2018Public PoC
Recommendation: Plan a near-term fix — a public PoC already exists.
An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data, aka "Windows Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.
Affected products
Microsoft · Internet Explorer 10Microsoft · Internet Explorer 11Microsoft · Internet Explorer 9public PoCs found — 2
cve_referencewww.exploit-db.com/exploits/45924/unverifiedexploitdbwww.exploit-db.com/exploits/45924unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →